Data Security Posture Management roles and permissions

This page lists the IAM roles and permissions for Data Security Posture Management. To search through all roles and permissions, see the role and permission index.

Data Security Posture Management roles

Role Permissions

(roles/dspm.serviceAgent)

Gives DSPM Service Account access to consumer resources.

aiplatform.artifacts.list

aiplatform.contexts.list

aiplatform.dataItems.list

aiplatform.datasets.get

aiplatform.datasets.list

aiplatform.endpoints.list

aiplatform.entityTypes.list

aiplatform.executions.list

aiplatform.metadataSchemas.list

aiplatform.modelEvaluations.list

aiplatform.models.list

aiplatform.trainingPipelines.list

aiplatform.tuningJobs.list

bigquery.datasets.createTagBinding

bigquery.datasets.deleteTagBinding

bigquery.datasets.listEffectiveTags

bigquery.datasets.listTagBindings

bigquery.jobs.create

bigquery.tables.createTagBinding

bigquery.tables.deleteTagBinding

bigquery.tables.getData

bigquery.tables.list

bigquery.tables.listEffectiveTags

bigquery.tables.listTagBindings

cloudasset.assets.exportResource

cloudasset.assets.listResource

cloudasset.assets.queryResource

cloudasset.assets.searchAllResources

cloudasset.feeds.create

cloudasset.feeds.delete

cloudasset.feeds.update

resourcemanager.hierarchyNodes.*

  • resourcemanager.hierarchyNodes.createTagBinding
  • resourcemanager.hierarchyNodes.deleteTagBinding
  • resourcemanager.hierarchyNodes.listEffectiveTags
  • resourcemanager.hierarchyNodes.listTagBindings

resourcemanager.tagKeys.create

resourcemanager.tagKeys.delete

resourcemanager.tagKeys.get

resourcemanager.tagKeys.getIamPolicy

resourcemanager.tagKeys.list

resourcemanager.tagKeys.update

resourcemanager.tagValueBindings.*

  • resourcemanager.tagValueBindings.create
  • resourcemanager.tagValueBindings.delete

resourcemanager.tagValues.create

resourcemanager.tagValues.delete

resourcemanager.tagValues.get

resourcemanager.tagValues.getIamPolicy

resourcemanager.tagValues.list

resourcemanager.tagValues.update

securitycenter.securityhealthanalyticssettings.*

  • securitycenter.securityhealthanalyticssettings.calculate
  • securitycenter.securityhealthanalyticssettings.get
  • securitycenter.securityhealthanalyticssettings.update

securitycentermanagement.effectiveSecurityHealthAnalyticsCustomModules.get

securitycentermanagement.securityHealthAnalyticsCustomModules.create

securitycentermanagement.securityHealthAnalyticsCustomModules.get

securityposture.operations.get

securityposture.postureDeployments.create

securityposture.postureDeployments.delete

securityposture.postures.create

securityposture.postures.get

storage.buckets.createTagBinding

storage.buckets.deleteTagBinding

storage.buckets.listEffectiveTags

storage.buckets.listTagBindings

Data Security Posture Management permissions

There are no IAM permissions for this service.